Live data from Hacker News

German federal office publishes Windows 10 telemetry analysis

ghacks.net

191–200 of 239 posts

Re: German federal office publishes Windows 10 telemetry analysis

#191

Earlier quoted context omitted.

Windows 10, spying on its user, is malware.

A domain like 'microsft.com' is used to trick users into thinking the communication is legitimate and to Microsoft. But why would the actual Microsoft need to engage in this?

Disclosure: Works for MS but not on anything related to the topic of discussion here. These are my personal opinions from experiences at multiple companies.

Any user-facing names obviously get reviewed by the whole departments that are dedicated to ensuring it fits with the brand, translates well into all languages, not offensive to anyone, etc.

For identifiers that are not expected to be user facing, they're likely to get code review, simple profanity filters, and certificate policy checks, plus whatever bikeshedding those particular dev+ops+networking teams want to have about it. For a service endpoint that's really only resolved in the guts of client code, I could easily imagine an individual dev just using an arbitrary name for the prototype, and then eventually finding that the service became useful and that it's just not worth updating all the existing clients for a cosmetic change mostly no one sees.

Also, you hear conversations like "so-and-so registered that name years ago for idea X, but that didn't really go anywhere, so we can just repurpose that since we know that it's both already working and unused".

So I wouldn't read any particular motivation into 'microsft.com'.

Re: German federal office publishes Windows 10 telemetry analysis

#192
post #123

Earlier quoted context omitted.

but why wouldnt they use microsoft-telemetry.com instead?

Probably for the very few people that use regex on their DNS servers to block Microsoft

This is most definitely the case. I can't think of any other reason they'd do this.

Re: German federal office publishes Windows 10 telemetry analysis

#193
post #6

I wish all governments did audits like this. Either the software would get less invasive, or we'd see Linux everywhere, wins all around. How bad is it that not even governments can use windows without the data vacuum being turned on? And they need to commission these investigations to even figure out what that means?

Well there's other issues with Linux on the desktop that doesn't let anybody except developers use it productively. You always have to weight your priorities, and getting stuff done is often number one priority.

Don't tell the ChromeOS team (and tens of millions of Chromebook/box) users that... though I doubt they'll be on any corporate IT wishlists (then again, they require very little support...).

Re: German federal office publishes Windows 10 telemetry analysis

#194
post #147
post #122

Earlier quoted context omitted.

The BSI is a federal office dedicated to IT security, not a company. It's more or less the German NSA, just without the spying part. That's done by other offices.

GP is talking about https://www.oo-software.com/en/company

Oh, that makes sense. Totally went past me when I commented. Thanks for pointing that out.

Re: German federal office publishes Windows 10 telemetry analysis

#195
post #107
post #6

I wish all governments did audits like this. Either the software would get less invasive, or we'd see Linux everywhere, wins all around. How bad is it that not even governments can use windows without the data vacuum being turned on? And they need to commission these investigations to even figure out what that means?

That is a nice wish but the german government is not as concerned with it's peoples privacy as you may think when you read stuff like this. The opposite is true. Germany sells it's people to everyone (including foreign spies who get offices directly at the backbone of the internet). We don't have much time left to educate people what computers are and how to keep your thoughts for yourself. All this fear and suspicio…

You wrote Germany but you're actually describing Australia.

Re: German federal office publishes Windows 10 telemetry analysis

#196
post #17

Has anything similar been done for Android phones with google services installed and Chrome browser?

For Chrome, there's the official whitepaper: https://www.google.com/chrome/privacy/whitepaper.html

I'd love to see independent verification that it is complete and truthful, of course.

Re: German federal office publishes Windows 10 telemetry analysis

#197

Earlier quoted context omitted.

>Windows 10 to turn off updates completely I did that 6 months ago best thing I ever did to win 10 so far.

Nothing bad has ever happened to an unpatched Windows system.

Malware is often more respectful of a compromised system than Microsoft.

Re: German federal office publishes Windows 10 telemetry analysis

#198
post #117

Earlier quoted context omitted.

If this “normal users are stupid” thing is supposed to be in favour of Linux then it’s a stale argument.

Normal users are not stupid. They just don't care.

How can you tell when the end result is identical? /s

Re: German federal office publishes Windows 10 telemetry analysis

#199

Earlier quoted context omitted.

Yep, which is why you disable Windows Update too. The people who work on Windows these days should probably all be fired. Out of a cannon. Into the sun.

Telling users to disable updates it's not a good recommendation.

How about, "don't use an OS that spies on you"?

Is that a good recommendation?

Re: German federal office publishes Windows 10 telemetry analysis

#200
post #60

Earlier quoted context omitted.

Yep. All of the Windows machines that I actually rely on for work—the ones that I need to be able to start up and immediately use, and need to be able to trust them to keep running without interruption or regression—are completely firewalled off from the public internet, so that they are secure both from malware, and unwanted updates. The rest of my work is done on other, more obedient operating systems. Windows 95 w…

My beef is that Microsoft created an update always culture (a good thing), but they are now “extending” the practice in ways that don’t reflect a customers best interest. The future, which is subscription models with limited time away from activation servers, breaks your needs fundamentally.

>The future, which is subscription models with limited time away from activation servers

My future is not an OS that spies on its users. I hope I'm not in the minority.

Post reply on HN